200-201 · Question #482
A member of the SOC team is checking the dashboard provided by the Cisco Firepower Manager for further isolation actions. According to NIST.SP800-61, in which phase of incident response is this action
The correct answer is B. detection and analyze phase. The phases of incident response according to NIST.SP800-61 are: Detection and Analysis Containment, Eradication, and Recovery Post-Incident Activity During the detection and analysis phase, SOC teams monitor systems for signs of incidents using various tools (like the Cisco Firep
Question
A member of the SOC team is checking the dashboard provided by the Cisco Firepower Manager for further isolation actions. According to NIST.SP800-61, in which phase of incident response is this action?
Options
- Apost-incident activity phase
- Bdetection and analyze phase
- Cpreparation phase
- Deradication and recovery phase
How the community answered
(25 responses)- A12% (3)
- B80% (20)
- C4% (1)
- D4% (1)
Explanation
The phases of incident response according to NIST.SP800-61 are: Detection and Analysis Containment, Eradication, and Recovery Post-Incident Activity During the detection and analysis phase, SOC teams monitor systems for signs of incidents using various tools (like the Cisco Firepower Manager). This is where they detect threats, investigate suspicious activity, and plan actions such as isolating compromised systems. This phase involves collecting and reviewing data, determining the scope of the incident, and deciding on initial response actions like isolation.
Topics
Community Discussion
No community discussion yet for this question.